Live data from Hacker News

What Exactly Did The US Government Ask Lavabit to Do?

xato.net

1–10 of 46 posts

Re: What Exactly Did The US Government Ask Lavabit to Do?

#4
This article gives no new information, it is stupid.

Now i will speculate:

As long as he does not know his customers passwords he can't retroactively view the customers mails, once the mails have been encrypted and the plain-text thrown away the stuff is unreachable.

So the US gov probably wanted him to save his customers passwords when they logged in.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#5
A device or piece of software designed to sniff the mail server to mail server connections would also be an option for broad based surveillance. Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. Most mail servers transmit messages in the clear to each other and only encrypt the server to client side.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#7
post #5

A device or piece of software designed to sniff the mail server to mail server connections would also be an option for broad based surveillance. Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. Most mail servers transmit messages in the clear to each other and only encrypt the server to client side.

Perhaps only a handful such as Google will use SSL but Google is a HUGE percentage of email.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#8
post #5

A device or piece of software designed to sniff the mail server to mail server connections would also be an option for broad based surveillance. Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. Most mail servers transmit messages in the clear to each other and only encrypt the server to client side.

> Only a handful of mail providers (like Google) have the option to encrypt traffic server to server.

SSL/TLS is available for everyone.

> Most mail servers transmit messages in the clear to each other and only encrypt the server to client side.

I hear this again and again, but I can't really find any data that confirms this claim one way or another. Anyone on HN running their own mailserver wanting to comment on how large portion of connections get encrypted?

Re: What Exactly Did The US Government Ask Lavabit to Do?

#9
post #4

This article gives no new information, it is stupid. Now i will speculate: As long as he does not know his customers passwords he can't retroactively view the customers mails, once the mails have been encrypted and the plain-text thrown away the stuff is unreachable. So the US gov probably wanted him to save his customers passwords when they logged in.

Right and the important point being that this isn't just about sniffing his network, it is the most invasive surveillance possible that would make his whole business a lie. The point of the article was to go through the logic to show that this would have been the only possibility for what they requested him to do.
Post reply on HN